Docker·ûºÅÁ´½ÓǰÌᾺÕù·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-03

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-15664£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.7


ÊÜÓ°ÏìµÄ°æ±¾


Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


DockerÊÇÃÀ¹úDocker¹«Ë¾µÄÒ»¿î¿ªÔ´µÄÀûÓÃÈÝÆ÷ÒýÇæ¡£¸Ã²úÆ·Ö§³ÖÔÚLinuxϵͳÉÏ´´½¨Ò»¸öÈÝÆ÷£¨ÇáÁ¿¼¶Ðé¹¹»ú£©²¢²¿ÊðºÍÔËÐÐÀûÓ÷¨Ê½£¬ÒÔ¼°Í¨¹ýÅäÖÃÎļþʵÏÖÀûÓ÷¨Ê½µÄ×Ô¶¯°ç×°Öᢲ¿ÊðºÍÉý¼¶¡£


Docker 18.06.1-ce-rc2¼°Ö®Ç°°æ±¾ÖеÄAPI¶Ëµã´æÔÚ·ûºÅÁ´½ÓǰÌᾺÕù·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÄÜÕýÈ·µØ¹ýÂË×ÊÔ´»òÎļþõè¾¶ÖеÄÌØÊâÔªËØ¡£¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶£¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷¡£


·ì϶ÑéÖ¤


·ì϶POC£ºhttps://seclists.org/oss-sec/2019/q2/131¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.docker.com/ ¡£


²Î¿¼Á´½Ó


https://seclists.org/oss-sec/2019/q2/131